LWA-2026-11171 confirmed malware

functions-framework-nodejs@1.0.0

Malicious code in functions-framework-nodejs (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (node install.js) executes the `id` command and POSTs the captured user/group identity along with the package name, version, and timestamp to the webhook collector webhook[.]site/c3d9086b-4ce8-41d1-8526-252bb4965500. The package name impersonates the Google Cloud Functions Framework.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 11:38 AM
analyzed
Aug 13, 2026, 11:38 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.